Amazon AWS AI Practitioner AIF-C01 AI Governance Compliance Services And Data Lifecycle Practice Test

 

 

This AWS Certified AI Practitioner AIF-C01 practice test focuses on ai governance compliance services and data lifecycle through original scenario-based questions aligned to AWS Exam Guide version 1.1 published April 30, 2026. Use the full ExamSnap AIF-C01 collection for broader practice across all five current exam domains. For broader exam preparation, review the Amazon AWS Certified AI Practitioner AIF-C01 Exam Dumps page.

Instructions: Select the best answer for each question. Review the rationale after answering. Each distractor includes a brief explanation of why it is not the strongest fit for the stated scenario.

Question 1

Nod Publishers is moving a fraud-review pilot from pilot to production. The key decision is how to identify supported software vulnerabilities and exposure findings in AWS workloads. Which option is the strongest fit if the team wants to limit exposure of sensitive data? The team will document the rationale for auditors and wants the recommendation to be defensible from the scenario facts. The control owner requires evidence from 5 test groups before the 195-day release review.

  1. AWS Trusted Advisor
  2. AWS shared responsibility model
  3. Policy in Amazon Bedrock AgentCore
  4. Amazon Macie
  5. Amazon Inspector

Correct answer: E

Why: Amazon Inspector provides automated vulnerability management for supported compute and container resources. It directly addresses the requirement in this scenario.

Option review:

A: Trusted Advisor provides checks that can support governance and operational improvement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: The responsibility boundary changes with the managed service, but customers always retain responsibilities such as data, identity, and correct configuration within their control. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: AgentCore Policy evaluates allowed or denied tool access at the infrastructure layer. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Macie helps identify sensitive data in S3 and can support data-protection governance. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Amazon Inspector provides automated vulnerability management for supported compute and container resources. It directly addresses the requirement in this scenario.

Learning point: Amazon Inspector – Amazon Inspector provides automated vulnerability management for supported compute and container resources.

Question 2

A workshop at Fabrikam Health focuses on a single decision: how to observe system health, model/application behavior, security signals, and policy compliance over time. Which option should the AI product manager recommend? The team wants the least complex technically correct choice that satisfies the requirement. The project has 2 downstream consumers and a monthly review of approximately 232 sampled interactions.

  1. Continuous monitoring
  2. Risk-based review strategy
  3. Written AI policy
  4. Data lifecycle policy
  5. Retention policy

Correct answer: A

Why: Governance is ongoing rather than a one-time launch activity. It directly addresses the requirement in this scenario.

Option review:

A: Governance is ongoing rather than a one-time launch activity. It directly addresses the requirement in this scenario.

B: Governance effort should scale with potential harm, autonomy, sensitivity, and business impact. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Policies establish organization-wide expectations and decision rights. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Continuous monitoring – Governance is ongoing rather than a one-time launch activity.

Question 3

For the compliance-assistant prototype at Wingtip Logistics, stakeholders need to classify the GenAI use case by the organization level of ownership/control and use that scope to guide security priorities. Which concept, service, or technique most directly addresses this goal? The workload has passed basic feasibility checks, so the remaining question is which approach best matches the requirement. The rollout spans 7 application teams, each using the same approved requirement set for the next 269 days.

  1. Team training
  2. Generative AI Security Scoping Matrix
  3. Continuous monitoring
  4. Transparency standard
  5. Data lifecycle policy

Correct answer: B

Why: The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines. It directly addresses the requirement in this scenario.

Option review:

A: Governance depends on people recognizing and following the controls, not only on technical enforcement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines. It directly addresses the requirement in this scenario.

C: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Transparency requirements create consistent disclosure and documentation expectations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Generative AI Security Scoping Matrix – The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines.

Question 4

Trey Research is comparing alternatives for its forecasting initiative. The AI product manager needs to record AWS API activity for auditing, investigation, and governance. Which option is most appropriate while trying to keep the design easy to explain? Stakeholders have ruled out a broad redesign and want the choice that most precisely addresses the stated need. The evaluation set contains examples from 4 business workflows and 306 recent production cases.

  1. AWS Config
  2. AWS Identity and Access Management (IAM)
  3. AWS CloudTrail
  4. Amazon Bedrock AgentCore Identity
  5. AWS Trusted Advisor

Correct answer: C

Why: CloudTrail captures account activity and API events across supported services. It directly addresses the requirement in this scenario.

Option review:

A: AWS Config tracks configuration state and can evaluate resources for compliance with defined rules. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: IAM roles, policies, and permissions are core controls for least-privilege access. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: CloudTrail captures account activity and API events across supported services. It directly addresses the requirement in this scenario.

D: AgentCore Identity integrates identity and authorization into agent workflows. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Trusted Advisor provides checks that can support governance and operational improvement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: AWS CloudTrail – CloudTrail captures account activity and API events across supported services.

Question 5

An architecture review at Bellows College has narrowed a customer-support modernization decision to one requirement: keep regulated data and processing in approved geographic locations when required. What should the operations manager select? Operational ownership is already assigned, so the team is comparing technical fit rather than staffing models. The initial rollout covers 343 internal users across 9 business units.

  1. Risk-based review strategy
  2. Logging policy
  3. Data lifecycle policy
  4. Data residency control
  5. Retention policy

Correct answer: D

Why: Residency requirements can constrain region, service, replication, and backup choices. It directly addresses the requirement in this scenario.

Option review:

A: Governance effort should scale with potential harm, autonomy, sensitivity, and business impact. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Residency requirements can constrain region, service, replication, and backup choices. It directly addresses the requirement in this scenario.

E: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Data residency control – Residency requirements can constrain region, service, replication, and backup choices.

Question 6

The AI product manager at Blue Yonder Airlines is preparing a recommendation for a agentic workflow trial. The recommendation must apply stronger approval and testing to high-impact AI uses than to low-risk internal experiments. Which choice is the best match? Existing application interfaces can accommodate any of the listed choices, so functional fit is the deciding factor. The workload processes about 380 requests during its busiest hour and has a documented fallback path.

  1. Retention policy
  2. Observability
  3. Transparency standard
  4. Continuous monitoring
  5. Risk-based review strategy

Correct answer: E

Why: Governance effort should scale with potential harm, autonomy, sensitivity, and business impact. It directly addresses the requirement in this scenario.

Option review:

A: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Transparency requirements create consistent disclosure and documentation expectations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Governance effort should scale with potential harm, autonomy, sensitivity, and business impact. It directly addresses the requirement in this scenario.

Learning point: Risk-based review strategy – Governance effort should scale with potential harm, autonomy, sensitivity, and business impact.

Question 7

Woodgrove Bank has completed discovery for a contact-center transformation. Before implementation, the operations manager must decide how to review supported best-practice checks and recommendations across categories such as security, resilience, performance, and cost. Which choice best satisfies that requirement? Assume the required AWS capabilities are available in the selected Region and normal governance controls are in place. The pilot uses 417 representative records from 3 approved data sources.

  1. AWS Trusted Advisor
  2. Policy in Amazon Bedrock AgentCore
  3. AWS Config
  4. AWS Artifact
  5. Encryption

Correct answer: A

Why: Trusted Advisor provides checks that can support governance and operational improvement. It directly addresses the requirement in this scenario.

Option review:

A: Trusted Advisor provides checks that can support governance and operational improvement. It directly addresses the requirement in this scenario.

B: AgentCore Policy evaluates allowed or denied tool access at the infrastructure layer. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: AWS Config tracks configuration state and can evaluate resources for compliance with defined rules. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: AWS Artifact provides on-demand access to AWS security and compliance documents. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Encryption reduces unauthorized disclosure risk when combined with proper key and access management. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: AWS Trusted Advisor – Trusted Advisor provides checks that can support governance and operational improvement.

Question 8

While planning a operations automation program, Wide World Importers identifies this requirement: keep data and logs only for the period required by business, legal, or regulatory needs. Which option should the AI product manager prioritize if the goal is to control recurring cost? The review committee wants a direct mapping from the requirement to the chosen capability. The first release supports 8 departments and is reviewed every 454 days.

  1. Observability
  2. Retention policy
  3. Generative AI Security Scoping Matrix
  4. Data residency control
  5. Data lifecycle policy

Correct answer: B

Why: Retention limits reduce risk and support records-management obligations. It directly addresses the requirement in this scenario.

Option review:

A: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Retention limits reduce risk and support records-management obligations. It directly addresses the requirement in this scenario.

C: The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Residency requirements can constrain region, service, replication, and backup choices. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Retention policy – Retention limits reduce risk and support records-management obligations.

Question 9

A proof of concept at VanArsdel Media exposed a design decision for the operations manager: the solution must ensure developers, reviewers, support staff, and business owners understand AI risks, controls, and escalation procedures. Which option most directly solves that problem? The solution will serve multiple internal teams, so the recommendation should be reusable without changing the core requirement. The service has a 491-millisecond internal response target for the affected workflow.

  1. Logging policy
  2. Continuous monitoring
  3. Team training
  4. Data residency control
  5. Observability

Correct answer: C

Why: Governance depends on people recognizing and following the controls, not only on technical enforcement. It directly addresses the requirement in this scenario.

Option review:

A: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Governance depends on people recognizing and following the controls, not only on technical enforcement. It directly addresses the requirement in this scenario.

D: Residency requirements can constrain region, service, replication, and backup choices. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Team training – Governance depends on people recognizing and following the controls, not only on technical enforcement.

Question 10

Datum Dynamics is documenting the target state for a internal search upgrade. The AI product manager needs a solution that can record and evaluate resource configurations against rules to support governance and compliance monitoring. Which option is the strongest fit? The decision must follow the workload characteristics rather than a preference for the largest model or newest service. The team is comparing 2 candidate designs after a 528-day proof of concept.

  1. Amazon Macie
  2. Amazon Bedrock Guardrails
  3. AWS Artifact
  4. AWS Config
  5. Amazon Bedrock AgentCore Identity

Correct answer: D

Why: AWS Config tracks configuration state and can evaluate resources for compliance with defined rules. It directly addresses the requirement in this scenario.

Option review:

A: Macie helps identify sensitive data in S3 and can support data-protection governance. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Bedrock Guardrails can help enforce content and data-safety policies around supported model calls. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: AWS Artifact provides on-demand access to AWS security and compliance documents. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: AWS Config tracks configuration state and can evaluate resources for compliance with defined rules. It directly addresses the requirement in this scenario.

E: AgentCore Identity integrates identity and authorization into agent workflows. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: AWS Config – AWS Config tracks configuration state and can evaluate resources for compliance with defined rules.

Question 11

Alpine Ski House is reviewing a document-intelligence project. The operations manager has one primary requirement: define how data is created, classified, used, archived, and deleted across the AI system. Which choice best fits the requirement? The security baseline is already defined; the decision here concerns the specific capability described in the requirement. The control owner requires evidence from 7 test groups before the 565-day release review.

  1. Logging policy
  2. Written AI policy
  3. Regular review cadence
  4. Retention policy
  5. Data lifecycle policy

Correct answer: E

Why: Lifecycle governance ensures data is managed consistently from acquisition through disposal. It directly addresses the requirement in this scenario.

Option review:

A: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Policies establish organization-wide expectations and decision rights. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: AI systems and threats evolve, so governance must be revisited. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Lifecycle governance ensures data is managed consistently from acquisition through disposal. It directly addresses the requirement in this scenario.

Learning point: Data lifecycle policy – Lifecycle governance ensures data is managed consistently from acquisition through disposal.

Question 12

During a design review for Humongous Insurance, the AI product manager must define approved uses, prohibited uses, data handling, oversight, and accountability before broad AI adoption. The team also wants to use current managed AWS capabilities. What should the team choose? The recommendation must solve the stated requirement without introducing unrelated platform complexity. The project has 4 downstream consumers and a monthly review of approximately 602 sampled interactions.

  1. Written AI policy
  2. Observability
  3. Transparency standard
  4. Regular review cadence
  5. Retention policy

Correct answer: A

Why: Policies establish organization-wide expectations and decision rights. It directly addresses the requirement in this scenario.

Option review:

A: Policies establish organization-wide expectations and decision rights. It directly addresses the requirement in this scenario.

B: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Transparency requirements create consistent disclosure and documentation expectations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: AI systems and threats evolve, so governance must be revisited. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Written AI policy – Policies establish organization-wide expectations and decision rights.

Question 13

Graphic Design Institute is moving a claims-processing redesign from pilot to production. The key decision is how to obtain AWS compliance reports and agreements relevant to audit and assurance work. Which option is the strongest fit if the team wants to limit exposure of sensitive data? The design must remain supportable after launch, but no additional feature is required beyond the stated need. The rollout spans 9 application teams, each using the same approved requirement set for the next 639 days.

  1. AWS Trusted Advisor
  2. AWS Artifact
  3. AWS Config
  4. Encryption
  5. AWS Identity and Access Management (IAM)

Correct answer: B

Why: AWS Artifact provides on-demand access to AWS security and compliance documents. It directly addresses the requirement in this scenario.

Option review:

A: Trusted Advisor provides checks that can support governance and operational improvement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: AWS Artifact provides on-demand access to AWS security and compliance documents. It directly addresses the requirement in this scenario.

C: AWS Config tracks configuration state and can evaluate resources for compliance with defined rules. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Encryption reduces unauthorized disclosure risk when combined with proper key and access management. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: IAM roles, policies, and permissions are core controls for least-privilege access. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: AWS Artifact – AWS Artifact provides on-demand access to AWS security and compliance documents.

Question 14

A workshop at Relecloud focuses on a single decision: how to collect metrics, logs, and traces that make AI application behavior understandable and diagnosable. Which option should the AI product manager recommend? A short pilot window means the team prefers an approach that can be evaluated with clear success criteria. The evaluation set contains examples from 6 business workflows and 676 recent production cases.

  1. Risk-based review strategy
  2. Written AI policy
  3. Observability
  4. Continuous monitoring
  5. Transparency standard

Correct answer: C

Why: Observability supports operations, audit, and incident response. It directly addresses the requirement in this scenario.

Option review:

A: Governance effort should scale with potential harm, autonomy, sensitivity, and business impact. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Policies establish organization-wide expectations and decision rights. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Observability supports operations, audit, and incident response. It directly addresses the requirement in this scenario.

D: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Transparency requirements create consistent disclosure and documentation expectations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Observability – Observability supports operations, audit, and incident response.

Question 15

For the developer-productivity pilot at Adventure Works Manufacturing, stakeholders need to define what users, reviewers, and auditors must be told about AI use, limitations, sources, and decision impact. Which concept, service, or technique most directly addresses this goal? The architecture board will reject a choice that addresses a different problem from the one described. The initial rollout covers 713 internal users across 3 business units.

  1. Continuous monitoring
  2. Generative AI Security Scoping Matrix
  3. Logging policy
  4. Transparency standard
  5. Observability

Correct answer: D

Why: Transparency requirements create consistent disclosure and documentation expectations. It directly addresses the requirement in this scenario.

Option review:

A: Governance is ongoing rather than a one-time launch activity. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Transparency requirements create consistent disclosure and documentation expectations. It directly addresses the requirement in this scenario.

E: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Transparency standard – Transparency requirements create consistent disclosure and documentation expectations.

Question 16

Proseware Services is comparing alternatives for its fraud-review pilot. The AI product manager needs to identify supported software vulnerabilities and exposure findings in AWS workloads. Which option is most appropriate while trying to keep the design easy to explain? Budget has been approved for the project, but the team still wants to avoid unnecessary recurring consumption. The workload processes about 750 requests during its busiest hour and has a documented fallback path.

  1. Amazon Bedrock AgentCore Identity
  2. AWS CloudTrail
  3. Amazon Macie
  4. AWS PrivateLink
  5. Amazon Inspector

Correct answer: E

Why: Amazon Inspector provides automated vulnerability management for supported compute and container resources. It directly addresses the requirement in this scenario.

Option review:

A: AgentCore Identity integrates identity and authorization into agent workflows. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: CloudTrail captures account activity and API events across supported services. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Macie helps identify sensitive data in S3 and can support data-protection governance. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: PrivateLink provides private connectivity to supported AWS services and endpoints. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Amazon Inspector provides automated vulnerability management for supported compute and container resources. It directly addresses the requirement in this scenario.

Learning point: Amazon Inspector – Amazon Inspector provides automated vulnerability management for supported compute and container resources.

Question 17

An architecture review at Lucerne Publishing has narrowed a analytics modernization decision to one requirement: define which AI interactions, tool actions, security events, and administrative changes must be recorded. What should the operations manager select? The team will validate the result with representative production examples before rollout. The pilot uses 787 representative records from 5 approved data sources.

  1. Logging policy
  2. Retention policy
  3. Observability
  4. Written AI policy
  5. Data lifecycle policy

Correct answer: A

Why: Logging requirements should be intentional and balanced with privacy and retention needs. It directly addresses the requirement in this scenario.

Option review:

A: Logging requirements should be intentional and balanced with privacy and retention needs. It directly addresses the requirement in this scenario.

B: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Policies establish organization-wide expectations and decision rights. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Logging policy – Logging requirements should be intentional and balanced with privacy and retention needs.

Question 18

The AI product manager at Lamna Healthcare is preparing a recommendation for a compliance-assistant prototype. The recommendation must reassess models, prompts, data, controls, vendors, and risk on a defined schedule and after material change. Which choice is the best match? The pilot has representative data, and the team will measure the selected approach against an agreed acceptance threshold. The first release supports 2 departments and is reviewed every 824 days.

  1. Retention policy
  2. Regular review cadence
  3. Risk-based review strategy
  4. Logging policy
  5. Team training

Correct answer: B

Why: AI systems and threats evolve, so governance must be revisited. It directly addresses the requirement in this scenario.

Option review:

A: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: AI systems and threats evolve, so governance must be revisited. It directly addresses the requirement in this scenario.

C: Governance effort should scale with potential harm, autonomy, sensitivity, and business impact. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Governance depends on people recognizing and following the controls, not only on technical enforcement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Regular review cadence – AI systems and threats evolve, so governance must be revisited.

Question 19

Contoso Retail has completed discovery for a forecasting initiative. Before implementation, the operations manager must decide how to review supported best-practice checks and recommendations across categories such as security, resilience, performance, and cost. Which choice best satisfies that requirement? The team will document the rationale for auditors and wants the recommendation to be defensible from the scenario facts. The service has a 861-millisecond internal response target for the affected workflow.

  1. Amazon Macie
  2. AWS Identity and Access Management (IAM)
  3. AWS Trusted Advisor
  4. Policy in Amazon Bedrock AgentCore
  5. Amazon Inspector

Correct answer: C

Why: Trusted Advisor provides checks that can support governance and operational improvement. It directly addresses the requirement in this scenario.

Option review:

A: Macie helps identify sensitive data in S3 and can support data-protection governance. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: IAM roles, policies, and permissions are core controls for least-privilege access. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Trusted Advisor provides checks that can support governance and operational improvement. It directly addresses the requirement in this scenario.

D: AgentCore Policy evaluates allowed or denied tool access at the infrastructure layer. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Amazon Inspector provides automated vulnerability management for supported compute and container resources. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: AWS Trusted Advisor – Trusted Advisor provides checks that can support governance and operational improvement.

Question 20

While planning a customer-support modernization, Fourth Coffee identifies this requirement: observe system health, model/application behavior, security signals, and policy compliance over time. Which option should the AI product manager prioritize if the goal is to control recurring cost? The team wants the least complex technically correct choice that satisfies the requirement. The team is comparing 4 candidate designs after a 898-day proof of concept.

  1. Retention policy
  2. Logging policy
  3. Team training
  4. Continuous monitoring
  5. Regular review cadence

Correct answer: D

Why: Governance is ongoing rather than a one-time launch activity. It directly addresses the requirement in this scenario.

Option review:

A: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Governance depends on people recognizing and following the controls, not only on technical enforcement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Governance is ongoing rather than a one-time launch activity. It directly addresses the requirement in this scenario.

E: AI systems and threats evolve, so governance must be revisited. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Continuous monitoring – Governance is ongoing rather than a one-time launch activity.

Question 21

A proof of concept at Margie Travel exposed a design decision for the operations manager: the solution must classify the GenAI use case by the organization level of ownership/control and use that scope to guide security priorities. Which option most directly solves that problem? The workload has passed basic feasibility checks, so the remaining question is which approach best matches the requirement. The control owner requires evidence from 9 test groups before the 935-day release review.

  1. Data lifecycle policy
  2. Observability
  3. Regular review cadence
  4. Team training
  5. Generative AI Security Scoping Matrix

Correct answer: E

Why: The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines. It directly addresses the requirement in this scenario.

Option review:

A: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: AI systems and threats evolve, so governance must be revisited. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Governance depends on people recognizing and following the controls, not only on technical enforcement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines. It directly addresses the requirement in this scenario.

Learning point: Generative AI Security Scoping Matrix – The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines.

Question 22

School of Fine Art is documenting the target state for a contact-center transformation. The AI product manager needs a solution that can obtain AWS compliance reports and agreements relevant to audit and assurance work. Which option is the strongest fit? Stakeholders have ruled out a broad redesign and want the choice that most precisely addresses the stated need. The project has 6 downstream consumers and a monthly review of approximately 972 sampled interactions.

  1. AWS Artifact
  2. Policy in Amazon Bedrock AgentCore
  3. AWS PrivateLink
  4. AWS shared responsibility model
  5. AWS Config

Correct answer: A

Why: AWS Artifact provides on-demand access to AWS security and compliance documents. It directly addresses the requirement in this scenario.

Option review:

A: AWS Artifact provides on-demand access to AWS security and compliance documents. It directly addresses the requirement in this scenario.

B: AgentCore Policy evaluates allowed or denied tool access at the infrastructure layer. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: PrivateLink provides private connectivity to supported AWS services and endpoints. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: The responsibility boundary changes with the managed service, but customers always retain responsibilities such as data, identity, and correct configuration within their control. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: AWS Config tracks configuration state and can evaluate resources for compliance with defined rules. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: AWS Artifact – AWS Artifact provides on-demand access to AWS security and compliance documents.

Question 23

Northwind Analytics is reviewing a operations automation program. The operations manager has one primary requirement: collect metrics, logs, and traces that make AI application behavior understandable and diagnosable. Which choice best fits the requirement? Operational ownership is already assigned, so the team is comparing technical fit rather than staffing models. The rollout spans 3 application teams, each using the same approved requirement set for the next 49 days.

  1. Transparency standard
  2. Observability
  3. Data lifecycle policy
  4. Written AI policy
  5. Retention policy

Correct answer: B

Why: Observability supports operations, audit, and incident response. It directly addresses the requirement in this scenario.

Option review:

A: Transparency requirements create consistent disclosure and documentation expectations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Observability supports operations, audit, and incident response. It directly addresses the requirement in this scenario.

C: Lifecycle governance ensures data is managed consistently from acquisition through disposal. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Policies establish organization-wide expectations and decision rights. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Observability – Observability supports operations, audit, and incident response.

Question 24

During a design review for Litware Financial, the AI product manager must define what users, reviewers, and auditors must be told about AI use, limitations, sources, and decision impact. The team also wants to use current managed AWS capabilities. What should the team choose? Existing application interfaces can accommodate any of the listed choices, so functional fit is the deciding factor. The evaluation set contains examples from 8 business workflows and 86 recent production cases.

  1. Observability
  2. Generative AI Security Scoping Matrix
  3. Transparency standard
  4. Team training
  5. Logging policy

Correct answer: C

Why: Transparency requirements create consistent disclosure and documentation expectations. It directly addresses the requirement in this scenario.

Option review:

A: Observability supports operations, audit, and incident response. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Transparency requirements create consistent disclosure and documentation expectations. It directly addresses the requirement in this scenario.

D: Governance depends on people recognizing and following the controls, not only on technical enforcement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Logging requirements should be intentional and balanced with privacy and retention needs. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: Transparency standard – Transparency requirements create consistent disclosure and documentation expectations.

Question 25

  1. Datum Research is moving a internal search upgrade from pilot to production. The key decision is how to record AWS API activity for auditing, investigation, and governance. Which option is the strongest fit if the team wants to limit exposure of sensitive data? Assume the required AWS capabilities are available in the selected Region and normal governance controls are in place. The initial rollout covers 123 internal users across 5 business units.
  2. Amazon Inspector
  3. AWS Artifact
  4. Encryption
  5. AWS CloudTrail
  6. AWS Trusted Advisor

Correct answer: D

Why: CloudTrail captures account activity and API events across supported services. It directly addresses the requirement in this scenario.

Option review:

A: Amazon Inspector provides automated vulnerability management for supported compute and container resources. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: AWS Artifact provides on-demand access to AWS security and compliance documents. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Encryption reduces unauthorized disclosure risk when combined with proper key and access management. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: CloudTrail captures account activity and API events across supported services. It directly addresses the requirement in this scenario.

E: Trusted Advisor provides checks that can support governance and operational improvement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

Learning point: AWS CloudTrail – CloudTrail captures account activity and API events across supported services.

Question 26

A workshop at Coho Winery focuses on a single decision: how to define which AI interactions, tool actions, security events, and administrative changes must be recorded. Which option should the AI product manager recommend? The review committee wants a direct mapping from the requirement to the chosen capability. The workload processes about 160 requests during its busiest hour and has a documented fallback path.

  1. Generative AI Security Scoping Matrix
  2. Data residency control
  3. Retention policy
  4. Team training
  5. Logging policy

Correct answer: E

Why: Logging requirements should be intentional and balanced with privacy and retention needs. It directly addresses the requirement in this scenario.

Option review:

A: The AWS matrix defines scopes from lower to higher organizational ownership of the model and related data and links them to security disciplines. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

B: Residency requirements can constrain region, service, replication, and backup choices. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

C: Retention limits reduce risk and support records-management obligations. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

D: Governance depends on people recognizing and following the controls, not only on technical enforcement. This can be appropriate in another scenario, but it does not most directly satisfy the requirement described here.

E: Logging requirements should be intentional and balanced with privacy and retention needs. It directly addresses the requirement in this scenario.

Learning point: Logging policy – Logging requirements should be intentional and balanced with privacy and retention needs.

Popular posts

img